Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-10803

Опубликовано: 22 мар. 2020
Источник: debian

Описание

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
phpmyadminfixed4:4.9.5+dfsg1-1package
phpmyadminfixed4:4.6.6-4+deb9u1stretchpackage

Примечания

  • https://www.phpmyadmin.net/security/PMASA-2020-4/

  • https://github.com/phpmyadmin/phpmyadmin/commit/46a7aa7cd4ff2be0eeb23721fbf71567bebe69a5

  • https://github.com/phpmyadmin/phpmyadmin/commit/6b9b2601d8af916659cde8aefd3a6eaadd10284a

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 5 лет назад

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.

CVSS3: 5.4
nvd
около 5 лет назад

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.

CVSS3: 5.4
github
около 3 лет назад

phpMyAdmin SQL injection vulnerability

suse-cvrf
около 5 лет назад

Security update for phpMyAdmin

suse-cvrf
больше 4 лет назад

Security update for phpMyAdmin

Уязвимость CVE-2020-10803